GlobalProtect Log Fields for PAN-OS 9.1.0 Through 9.1.2
Focus
Focus

GlobalProtect Log Fields for PAN-OS 9.1.0 Through 9.1.2

Table of Contents

GlobalProtect Log Fields for PAN-OS 9.1.0 Through 9.1.2

View GlobalProtect log field information for PAN-OS 9.1.0 through 9.1.2 using syslog.
Format: FUTURE_USE, Receive Time, Serial Number, Sequence Number, Action Flags, Type, FUTURE_USE, FUTURE_USE, Generated Time, Virtual System, Event ID, Stage, Authentication Method, Tunnel Type, Source User, Source Region, Machine Name, Public IP, Public IPv6, Private IP, Private IPv6, Host ID, Serial Number, Client Version, Client OS, Client OS Version, Repeat Count, Reason, Error, Description, Status, Location, Login Duration, Connect Method, Error Code, Portal
Field Name
Description
Receive Time (receive_time)
The time that the log was received at the management plane.
Serial # (serial)
The serial number of the firewall that generated the log.
Sequence Number (seqno)
A 64-bit log entry identifier incremented sequentially; each log type has a unique number space.
Action Flags (actionflags)
A bit field indicating if the log was forwarded to Panorama.
Type (type)
Specifies the type of log; value is GLOBALPROTECT.
Threat/Content Type (subtype)
Subtype of threat log. Values include the following:
  • data—Data pattern matching a Data Filtering profile.
  • file—File type matching a File Blocking profile.
  • flood—Flood detected via a Zone Protection profile.
  • packet—Packet-based attack protection triggered by a Zone Protection profile.
  • scan—Scan detected via a Zone Protection profile.
  • spyware —Spyware detected via an Anti-Spyware profile.
  • url—URL filtering log.
  • virus—Virus detected via an Antivirus profile.
  • vulnerability —Vulnerability exploit detected via a Vulnerability Protection profile.
  • wildfire —A WildFire verdict generated when the firewall submits a file to WildFire per a WildFire Analysis profile and a verdict (malicious, phishing, grayware, or benign, depending on what you are logging) is logged in the WildFire Submissions log.
  • wildfire-virus—Virus detected via an Antivirus profile.
Generate Time (time_generated)
The time that the log was generated on the dataplane.
Virtual System (vsys)
The Virtual System associated with the session.
Event ID (eventid)
A string showing the name of the event.
Stage (stage)
A string showing the stage of the connection (for example,
before-login
,
login
, or
tunnel
).
Authentication Method (auth_method)
A string showing the authentication type, such as
LDAP
,
RADIUS
, or
SAML
.
Tunnel Type (tunnel_type)
The type of tunnel (either SSLVPN or IPSec).
Source User (srcuser)
The username of the user who initiated the session.
Source Region (srcregion)
The region for the user who initiated the session.
Machine Name (machinename)
The name of the user’s machine.
Public IP (public_ip)
The public IP address for the user who initiated the session.
Public IPv6 (public_ipv6)
The public IPv6 address for the user who initiated the session.
Private IP (private_ip)
The private IP address for the user who initiated the session.
Private IPv6 (private_ipv6)
The private IPv6 address for the user who initiated the session.
Host ID (hostid)
The unique ID that GlobalProtect assigns to identify the host.
Serial Number (serialnumber)
The serial number of the user’s machine or device.
Client Version (client_ver)
The client’s GlobalProtect app version.
Client OS (client_os)
The client device’s OS type (for example, Windows or Linux).
Client OS Version (client_os_ver)
The client device’s OS version.
Repeat Count (repeatcnt)
The number of sessions with the same source IP address, destination IP address, application, and subtype that GlobalProtect has detected within the last five seconds.
Reason (reason)
A string that shows the reason for the quarantine.
Error (error)
A string showing that error that has occurred in any event.
Description (opaque)
Additional information for any event that has occurred.
Status (status)
The status (success or failure) of the event.
Location (location)
A string showing the administrator-defined location of the GlobalProtect portal or gateway.
Login Duration (login_duration)
The length of time, in seconds, the user is connected to the GlobalProtect gateway from logging in to logging out.
Connect Method (connect_method)
A string showing the how the GlobalProtect app connects to Gateway, (for example,
on-demand
or
user-logon
.
Error Code (error_code)
An integer associated with any errors that occurred.
Portal (portal)
The name of the GlobalProtect portal or gateway.

Recommended For You